File tree Expand file tree Collapse file tree 3 files changed +24
-2
lines changed Expand file tree Collapse file tree 3 files changed +24
-2
lines changed Original file line number Diff line number Diff line change
1
+ ## 0.15.5
2
+
3
+ * [ deps] upgrade BC to version 1.81
4
+ * Improving completeness of ASN1 encoding/decoding (#335 )
5
+ * [ fix] OpenSSL::X509::CRL#to_pem when building CRL from scratch (#163 )
6
+ * [ fix] OpenSSL::ASN1::ASN1Data encoding/decoding compatibility (#265 )
7
+
8
+ ## 0.15.4
9
+
10
+ * Verify hostname by default
11
+
12
+ This addresses ** CVE-2025 -46551** and ** GHSA-72qj -48g4-5xgx** .
13
+
14
+ Users can work around this by applying this patch manually to their
15
+ own jruby-openssl and jruby installs, or by re-enabling hostname
16
+ verification with the following code early in application boot:
17
+ ``` ruby
18
+ require ' openssl'
19
+
20
+ OpenSSL ::SSL ::SSLContext ::DEFAULT_PARAMS [:verify_hostname ] = true
21
+ ```
22
+
1
23
## 0.15.3
2
24
3
25
* [ fix] keep curve name when group is set into another key
Original file line number Diff line number Diff line change 1
1
module JOpenSSL
2
- VERSION = '0.15.5.dev '
2
+ VERSION = '0.15.5'
3
3
BOUNCY_CASTLE_VERSION = '1.81'
4
4
end
5
5
Original file line number Diff line number Diff line change @@ -11,7 +11,7 @@ DO NOT MODIFY - GENERATED CODE
11
11
<modelVersion >4.0.0</modelVersion >
12
12
<groupId >rubygems</groupId >
13
13
<artifactId >jruby-openssl</artifactId >
14
- <version >0.15.5.dev-SNAPSHOT </version >
14
+ <version >0.15.5</version >
15
15
<packaging >gem</packaging >
16
16
<name >JRuby OpenSSL</name >
17
17
<description >JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library.</description >
You can’t perform that action at this time.
0 commit comments